Server-Side Request Forgery Vulnerability in Feedmob FM-MCP-Servers
CVE-2026-19770
Key Information:
- Vendor
Feedmob
- Status
- Vendor
- CVE Published:
- 14 August 2026
Badges
What is CVE-2026-19770?
A security vulnerability exists in Feedmob's FM-MCP-Servers version 0.0.3, specifically within the 'downloadReport' function located in the Download Endpoint module. This issue arises from the manipulation of the 'downloadUrl' argument, enabling an attacker to perform server-side request forgery attacks. Although the exploit can be executed only from a local environment, it remains publicly accessible. The Feedmob team was notified of this vulnerability through an issue report but has yet to provide a response or implement a fix.
Affected Version(s)
fm-mcp-servers 0.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
